Database/Control plane, storage & DevOps

Crossplane package manager (cosign signature verification via ImageConfig): SUPPLY CHAIN, TIME-OF-CHECK TO TIME-OF-USE
Impact
SUPPLY CHAIN, TIME-OF-CHECK TO TIME-OF-USE: Crossplane verifies a package's signature and then installs a different package. When a package is referenced by tag rather than digest, the package manager resolves that tag separately for the verification step and for the pull step, so a malicious registry serves a correctly signed image to the verifier and an unsigned one to the installer. Signature verification reports success and unsigned attacker code lands in the cluster with whatever privileges the Crossplane package holds — and Crossplane packages are control-plane extensions that reconcile cloud and infrastructure resources, so that is typically broad. The failure mode is the worst kind for an operator: the control is enabled, the dashboard is green, and it is providing no protection.
Who can reach it
Network, unauthenticated from the attacker's side: requires a malicious or compromised OCI registry able to vary what it serves per request. Only affects users who enable signature verification, install by tag rather than digest, and pull from registries they do not control.
What to do
Install packages by image digest rather than tag — this defeats the race entirely and is the vendor's stated mitigation as well as general best practice. Upgrade to Crossplane 2.3.3 or 2.2.3, where the tag is resolved once and the resulting digest is used for both verification and fetch. Note the maintainers are not backporting to 1.20, so 1.20 clusters must rely on digest pinning permanently.
References
Related entries
- Ceph CephX: malleable, unauthenticated tickets let a low-privilege key be forged into Manager, MDS or OSD accessCVE-2025-30156 · Ceph CephX authentication protocol (unauthenticated AES-128-CBC ticket encryption)High
- Ceph CephX (authentication protocol): A tenant holding one low-privilege CephX client key ends up with cluster-wideNCVD-2025-016-ceph-cephx-authentication-protoc · Ceph CephX (authentication protocol)High
- GlusterFS (brick, server-rpc-fops.c): Multiple stack buffer overflows from fixed-size alloca() allocations in the brickCVE-2018-10907 · GlusterFS (brick, server-rpc-fops.c)High
- GlusterFS (brick, gfs3_symlink_req): Symlink creation is not confined to the volume, so a client plants a link pointingCVE-2018-10928 · GlusterFS (brick, gfs3_symlink_req)High
- NetApp Clustered Data ONTAP export policy enforcement (SMBv2/SMBv3): Export policy rules marked read-only are notCVE-2018-5490 · NetApp Clustered Data ONTAP export policy enforcement (SMBv2/SMBv3)High
- Schneider Electric Data Center Expert 7.5.0 and earlier - zip upload: A crafted zip uploaded through the DCE UI canCVE-2018-7807 · Schneider Electric Data Center Expert 7.5.0 and earlier - zip uploadHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.